Weaknesses of type CWE-22

5,988 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-27523MEDIUMOpenClaw < 2026.2.24 - Sandbox Bind Validation Bypass via Symlink-Parent Missing-Leaf PathsEPSS 0.4%CVE-2026-23745HIGHnode-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path SanitizationEPSS 0.4%CVE-2025-64107HIGHCursor is Vulnerable to Path Manipulation Using Backslashes on WindowsEPSS 0.4%CVE-2025-34238MEDIUMAdvantech WebAccess/VPN < 1.1.5 Path Traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction()EPSS 0.4%CVE-2026-76434MEDIUMCisco Identity Services Engine Arbitrary File Read VulnerabilityEPSS 0.4%CVE-2025-43889MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4, LTS2024 release VerEPSS 0.4%CVE-2026-89021MEDIUMMikroTik RouterOS Path Traversal via Container OCI/tar Image ExtractionEPSS 0.4%CVE-2026-52349HIGHDirectory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute aEPSS 0.4%CVE-2026-6829MEDIUMnesquena hermes-webui Arbitrary Workspace Directory AccessEPSS 0.4%CVE-2025-69055MEDIUMWordPress BM Content Builder plugin < 3.16.3.3 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2024-6044MEDIUMD-Link router - Arbitrary File ReadingEPSS 0.4%CVE-2024-55659HIGHSiYuan has an arbitrary file write in the host via /api/asset/uploadEPSS 0.4%CVE-2026-102457HIGHDigiWin|EasyFlow .NET - Arbitrary File ReadEPSS 0.4%CVE-2025-6233MEDIUMArbitrary file read by system admin via path traversalEPSS 0.4%CVE-2026-10094CRITICALPath Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026EPSS 0.4%CVE-2026-65939MEDIUMWhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.EPSS 0.4%CVE-2026-39977HIGHflatpak-builder has a path traversal leading to arbitrary file read on host when installing licence filesEPSS 0.4%CVE-2026-56839HIGHPraisonAI Code agent tools fail open without a workspace boundaryEPSS 0.4%CVE-2023-30584HIGHA vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improEPSS 0.4%CVE-2025-41396MEDIUMA path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwritten by a product usEPSS 0.4%